PT-2025-5266 · Coolify · Coolify
Angelej
·
Published
2025-01-24
·
Updated
2025-01-31
·
CVE-2025-24025
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Coolify versions prior to 4.0.0-beta.380
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. The issue arises when the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, leading to cross-site scripting.
Recommendations
For versions prior to 4.0.0-beta.380, update to version 4.0.0-beta.380 to resolve the issue. As a temporary workaround, consider restricting access to the tags page or disabling the search functionality until the update is applied.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coolify